Penetration testing

Penetration testing that proves real risk

A controlled, authorised simulation of a genuine attack — manually chaining weaknesses to show real impact, and exactly how to stop it.

Web & APINetworkCloudSocial engineering

Test types

Where we test

01

Web application

Auth, authorisation, business logic and injection across roles.

02

API testing

REST and GraphQL access control and data exposure.

03

Network & infrastructure

External and internal services, segmentation, escalation paths.

04

Cloud configuration

Identity, storage, network and workload misconfigurations.

05

Social engineering

Consent-based phishing that measures human resilience.

06

Mobile & thick client

Mobile apps and back ends: storage, transport, API misuse.

Methodology

How we run a test

Aligned with recognised industry methodology and the OWASP Testing Guide.

01

Rules of engagement

Scope and escalation contacts authorised in writing first.

02

Mapping

Attack surface, users and tech mapped without impacting uptime.

03

Analysis

Manual testing finds what a scanner alone would miss.

04

Safe exploitation

Impact confirmed with the least intrusive proof possible.

05

Reporting

Prioritised findings with evidence and business impact.

06

Verification

Fixes retested and an updated status issued.

Severity model

How we rate findings

Likelihood and business impact, aligned with CVSS.

SeverityMeaningResponse
CriticalDirect, high-impact compromise.Fix immediately.
HighSerious, realistically exploitable.Fix this cycle.
MediumMeaningful, often conditional risk.Plan a fix soon.
LowLimited impact or hardening.Address as maintenance.

Rules of engagement

Safe, legal, and in scope

Every test is bounded by a signed agreement. We only ever test assets you are authorised to have tested.

  • Written authorisation and defined scope
  • Production-safe techniques
  • No data exfiltration beyond proof
  • Findings shared securely
  • Immediate contact on anything high-risk
rules-of-engagement.txt
authorised_by = client CISOscope = in-scope assets onlydata = proof-onlyescalation = immediate on critical

Next step

Ready to test your application?

Send the target and your goals; we propose scope, timeline and a fixed price.